A vulnerability in Automated Logic WebCTRL 7.0 could allow an attacker to send a maliciously crafted URL, which when visited by an authenticated WebCTRL user, could result in the redirection of the user to a malicious webpage via "index.jsp"
Solution:
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://www.corporate.carrier.com/product-security/advisories-resources/ | vendor advisory |
https://www.cisa.gov/news-events/ics-advisories/ | government resource |